πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Hackers Found Phishing for Facebook Credentials πŸ•΄

A "very realistic-looking" login prompt is designed to capture users' Facebook credentials, researchers report.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Staffing Shortage Makes Vulnerabilities Worse πŸ•΄

Businesses don't have sufficient staff to find vulnerabilities or protect against their exploit, according to a new report by Ponemon Institute.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-1695

IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134177.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Network recovery advice: Experts weigh in πŸ”

In the old days, you just had redundant everything, and disaster recovery meant switching over. Not so in the world of cloud computing, security nightmares, and virtual everything.

πŸ“– Read

via "Security on TechRepublic".
❌ Data Breach Bonanza: Dating Apps, Equifax, Mass Credential Dumps ❌

Data-exposure "lowlights" for the week ending Feb. 15, 2019.

πŸ“– Read

via "Threatpost | The first stop for security news".
ATENTIONβ€Ό New - CVE-2015-4617

Vulnerability in Easy2map-photos WordPress Plugin v1.09 MapPinImageUpload.php and MapPinIconSave.php allows path traversal when specifying file names creating files outside of the upload directory.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-4615

Vulnerability in Easy2map-photos WordPress Plugin v1.09 allows SQL Injection via unsanitized mapTemplateName, mapName, mapSettingsXML, parentCSSXML, photoCSSXML, mapCSSXML, mapHTML,mapID variables

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-5654

Vulnerability in YingZhi Python Programming Language v1.9 allows arbitrary anonymous uploads to the phone's storage

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-2565

A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the webserver.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-2516

Vulnerability in FileUtils v0.7, Ruby Gem Fileutils <= v0.7 Command Injection vulnerability in user supplied url variable that is passed to the shell.

πŸ“– Read

via "National Vulnerability Database".
❌ Where’s the Equifax Data? Does It Matter? ❌

Threat-hunters say the breached data from the massive Equifax incident is nowhere to be found, indicating a spy job.

πŸ“– Read

via "Threatpost | The first stop for security news".
ATENTIONβ€Ό New - CVE-2016-10742

Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the request parameter.

πŸ“– Read

via "National Vulnerability Database".
⚠ Monday review – the hot 28 stories of the week ⚠

From McDonald's hamburglars to 1000-character phishing urls, and everything between. It's weekly roundup time.

πŸ“– Read

via "Naked Security".
⚠ Will the EU’s new copyright directive ruin the web? ⚠

Articles 11 and 13 live on, with the dreaded 'link tax', 'meme killer', 'censorship machine' and all.

πŸ“– Read

via "Naked Security".
⚠ Opera integrates a cryptocurrency wallet – is this Web 3.0? ⚠

When it appears in the next few weeks, the next version of Opera (β€œReborn 3” or β€œR3”) for Windows, Mac and Linux will become the first mainstream desktop browser to integrate a cryptocurrency wallet.

πŸ“– Read

via "Naked Security".
⚠ Mega-crackers back with nearly 100 million new stolen data records ⚠

Sounds like the crooks who tried to sell more than 600 million records last week are back with nearly 100 million more...

πŸ“– Read

via "Naked Security".
πŸ•΄ Privacy Ops: The New Nexus for CISOs & DPOs πŸ•΄

No longer can privacy be an isolated function managed by legal or compliance departments with little or no connection to the organization's underlying security technology.

πŸ“– Read

via "Dark Reading: ".
βš™οΈ I Am Not Associated with Swift Recovery Ltd. βš™οΈ

It seems that someone from a company called Swift Recovery Ltd. is impersonating me -- at least on Telegram. The person is using a photo of me, and is using details of my life available on Wikipedia to convince people that they are me.They are not.If anyone has any more information -- stories, screen shots of chats, etc. -- please forward them to me.


πŸ“– Read

via "Schneier on Security".
❌ When Cyberattacks Pack a Physical Punch ❌

Physical security goes hand in hand with cyberdefense. What happens when – as we see all too often – the physical side is overlooked?

πŸ“– Read

via "Threatpost | The first stop for security news".
⚠ Fake text generator is so good its creators don’t want to release full version ⚠

OpenAI has created what amounts to a text version of a deepfake - and it’s too scared for humanity to release the full version.

πŸ“– Read

via "Naked Security".
⚠ Facebook acts like a law-breaking β€˜digital gangster’, says official report ⚠

Facebook considers itself to be β€œahead of and beyond the law,” UK lawmakers said in a report about "disinformation and 'fake news.'"

πŸ“– Read

via "Naked Security".